I Couldn't Find the AI Security Gateway I Needed. So I Built My Own.
I've been searching for an AI gateway solution that puts Security first, not as an afterthought bolted onto an API management platform, but as the core design principle.
https://t.co/k2KiNeE6bX
NPM package NX compromised!
The nx package versions 20.11.0 and 21.7.0 appears to be compromised with code published that would attempt malicious actions including modifying the installers .bashrc/.zshrc.
https://t.co/KeuG73FWYl
๐ฅ NEW: Cobalt Strike BOF simulation modules are live!
Introducing ATTACKIFY's new Cobalt Strike BOF simulation modules - so your blue team can finally test defenses against these post-exploitation techniques like:
โ COFF loading patterns
โ Direct syscall techniques
โ Reflective loading
โ TrustedSec BOF collections
โ Memory injection workflows and more...
No more guessing if your EDR catches Cobalt Strike BOFs ๐ฏ
https://t.co/WvDd2kMycL
Sign-up for a FREE account at ATTACKIFY and start validating your security today!
https://t.co/71zL2K8PcJ
#CyberSecurity #BOF #CobaltStrike #EDR #ThreatSimulation #blueteam #ATTACKIFY
๐ Meet L.U.K.E, our new AI Engineer at ATTACKIFY!
After a simulation, Luke will write custom detection rules, explain findings in plain English, and suggest fixes that actually work.
One beta tester: "Like having a senior analyst who never sleeps" ๐คโ๏ธ
To our PRO customers, Luke is waiting for you in the simulation results tab!
Luke will be growing and learning new skills over the next year to bring you even more value throughout the ATTACKIFY platform
#ATTACKIFY #AIforSecurity
Turns out, compliance reporting doesn't have to make you cry! ๐
Our new Compliance Dashboard maps your ATTACKIFY security tests and results directly to SOC2, NIST, CIS, PCI & more.
The gap analysis shows exactly where you're vulnerable with actual test data backing it up.
#ATTACKIFY #ComplianceAutomation
๐ JUST LAUNCHED: ATTACKIFY 3.0 is live!
โ New compliance dashboards
โ Enhanced security testing
โ Our own AI Engineer (we named him Luke!)
The biggest update we've ever released that goes way more than skin deep.
Stay tuned as we unveil more exciting features and updates!
If you don't have an account already, get a free starter account at:
https://t.co/ZkDhOssCSS
#Cybersecurity #ATTACKIFY
๐ New Feature: TableTop Exercises! ๐ก๏ธ
We're excited to announce the new TableTop Exercises feature in ATTACKIFY! This new addition to our platform is designed to help you & your team improve your cyber incident response skills through interactive, scenario-based learning.
TableTop Exercises in ATTACKIFY:
โข Diverse selection of tabletop scenarios
โข Step-by-step guided exercise process
โข Timed challenges for real-world pressure
โข Hint system for guidance and learning
โข Progress saving for flexibility
โข Local browser storage for privacy and security
Read more about it on our blog:
https://t.co/aKcweCrkZz
#tabletop #CyberSecurity
๐New ATTACKIFY Module: APT41 Sandboxie DLL Side-Loading ๐ค
@Threatlabz recently covered some of the new techniques & updated tools from #APT41. We started adding modules to accurately simulate the new Sandboxie DLL side-loading technique covered in their recent blog.
๐ Test your defenses against sophisticated threats
๐ก๏ธ Improve detection of stealthy payload execution
๐ฌ Hands-on experience with real-world APT tactics
Elevate your cyber defense game with our advanced APT emulations and malicious behaviour simulations!
Sign up for FREE at https://t.co/gyGqzp3uM7
๐ Bridging MITRE ATT&CK with ATTACKIFY for Advanced Threat Actor Emulation!
Exciting news! We've just released a new CLI tool in beta to compliment ATTACKIFY that will help you instantly run emulations based on any @MITREattack Threat Actor Group Profiles.
๐ฏ Map ATT&CK TTPs to ATTACKIFY Modules
๐ก๏ธ Automate Threat Actor Emulations
๐ Run Custom APT Campaigns Instantly
๐ Improve Security Controls as data is published!
Learn more from our blog: https://t.co/7m0M0RemWk
#Cybersecurity #ThreatEmulation #ThreatIntel
๐ New Module Alert! ๐
We're excited to introduce our latest ATTACKIFY module targeting CVE-2024-26229, a vulnerability in the Windows CSC Service.
๐ Key Features:
- Test & Validate Security Controls: Focus on local privilege escalation detection & prevention.
- Real-World Simulation: Attempts to safely exploit the vulnerability & runs whoami.exe to verify SYSTEM privileges.
Enhance your security posture with ATTACKIFY today! Test your security controls against many of our privilege escalation modules and more๐ช
https://t.co/OmNhtTq440
#CyberSecurity
๐ New ATTACKIFY Module: Network Discovery Mapper! ๐
Discover hidden network paths and visualize your organization's topology from the ATTACKERS point of view ๐
Use some of the discovery modules in ATTACKIFY to emulate attacker reconnaissance, identify gaps, and strengthen your overall security posture.
Sign up for a FREE account: https://t.co/gyGqzp3uM7
#cybersecurity #CyberThreat
๐จ Attention Australian Businesses and Educational Institutes! ๐จ
We're offering FREE Professional ATTACKIFY accounts for the rest of 2024 if you register for a FREE account in June.
We want to help protect against the current surge in cyber attacks seen in Australia lately.
Don't miss out on this opportunity to improve your overall security posture now!
- Audit Endpoints
- Test, Validate & Improve Security Controls
- Perform Security Maturity Assessments
- Perform External Asset Discover and Vulnerability Scanning
https://t.co/Cnavzikmv2
(Must be a registered business within Australia)
#CyberSecurity #Australia #ATTACKIFY #JuneFreeOffer
@attackify partnering with @TidalCyber and adding to their amazing product registry of data empowering users to make more informed decisions by enabling them to seamlessly integrate and analyze data for better testing and threat-informed strategies.
We've added @scapecom ATTACKIFY Threat Simulation to our Vendor Registry!
Testing is a key aspect of #ThreatInformedDefense to validate assumptions in the face of a particular threat. ATTACKIFY mappings for @MITREattack are also now available. Learn more: https://t.co/Ibq0L2eNZa
We've added @scapecom ATTACKIFY Threat Simulation to our Vendor Registry!
Testing is a key aspect of #ThreatInformedDefense to validate assumptions in the face of a particular threat. ATTACKIFY mappings for @MITREattack are also now available. Learn more: https://t.co/Ibq0L2eNZa
๐ก๏ธ So, what is ATTACKIFY?
A cybersecurity Swiss Army knife ๐!
A robust platform for organizations big & small, offering everything from:
๐ค Breach & Attack Simulations
๐ Phishing Tests
๐ก๏ธ Endpoint Audit & Security Health Checks
๐Attack Surface Discovery & Vulnerability Scanning
โ๏ธCyber Security Readiness Self Assessments
Affordable? Absolutely!
Elevate your cyber defense game with us!
Sign up for FREE at https://t.co/gyGqzp3uM7
#CyberSecurity #ATTACKIFY #DigitalDefense #CyberAttack #blueteam #redteam #purpleteam
๐ Exciting Update: ATTACKIFY - Attack Surface Management!
In our new blog we walk you through the new Attack Surface Management capabilities, including an advanced RECON module to discover and fingerprint Internet-facing assets and asset Vulnerability Scanner ๐ก๏ธ
Perfect for any organization, big or small - and it's accessible with our STARTER accounts! Dive into our latest breakthroughs and elevate your cybersecurity strategy with us.
Read more: https://t.co/OlfJIBRn13
#CyberSecurityAwareness #attacksurface #ITSecurity
๐ Exciting news from ATTACKIFY!๐
๐ We're happy to announce the integration of our Internet-facing Asset Vulnerability Scanner within #ATTACKIFY, powered by the renowned @pdnuclei from @pdiscoveryio. Dive deeper into cybersecurity with the ability to run vulnerability scans on your external assets โ another tool added to the robust ATTACKIFY suite.
Now available for all accounts, including our free STARTER accounts!
๐ก๏ธ Elevate Your Cybersecurity Game:
๐ฏ Threat Simulations and Attacker Emulation
๐ ๏ธ Security Control Checks and Endpoint Auditing
๐ช Phishing Simulations
๐ Vulnerability Scanning (local and now external assets!)
All designed to test & fortify your defenses, right from ATTACKIFY's integrated platform.
๐ Start Securing Your Assets Today: https://t.co/Cnavzikmv2
#CyberSecurity #redteam #VulnerabilityScanning #infosecurity #purpleteam #blueteam
๐จ New ATTACKIFY Module - EDR Bypasses ๐จ
๐ค EDR Bypass - Call Stack Spoofing
Researchers are dedicating significant time to exploring methods for circumventing EDR solutions. This new module employs call stack spoofing and indirect syscall methods aimed at evading the hooking of NTDLL to bypass various EDR detections. If successful the module will execute shellcode from the stack to launch calc.exe.
๐ก Defend by understanding the offense! Get hands-on with EDR bypass techniques and improve your detection and response times. Jump into the attacker's seat, risk-free.
https://t.co/Cnavzikmv2
๐ฏ Sharpen your defense today with ATTACKIFY!
#edrbypasses #BlueTeam #purpleteam #CyberSecurity #CyberAttack #redteam
๐จ New ATT&CK Technique & New ATTACKIFY Module Alert ๐จ
๐ค whoami.exe Alternative Methods
Traditional threat detection relies on detection of attackers executing the Windows whoami.exe utility on compromised endpoints once they have gained remote access. More advanced and cautious attackers may avoid running whoami.exe entirely and rely on less obvious methods.
This new module will attempt to identify the current user on the endpoint using alternative methods to whoami.exe with the goal of building more sophisticated detection and response capabilities.
๐ก Defend by understanding the offense! Get hands-on with these additional techniques and find out who is running alternative whoami.exe methods on your endpoints. Jump into the attacker's seat, risk-free.
https://t.co/Cnavzikmv2
๐ฏ Sharpen your defence today at ATTACKIFY - Your first simulation is on us, OK maybe a whole bunch more!
#blueteam #cyberattacks #purpleteam #cybersecurity #WHOAMI